What Is the Risk of a Malleability Attack on an Exchange?
Before SegWit, an exchange could face issues if a withdrawal transaction was sent, and then a malleability attack changed its TXID before confirmation. The exchange's software, expecting the original TXID, might fail to track the payment, potentially leading to a second withdrawal (double-spend) if not properly handled.